From 3c50408e07e977655d20200e93e85ad51cead6bd Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 2 Oct 2026 01:38:49 +0100 Subject: [PATCH] ci(actions-lock): empty the secret-scanner.yml key for the reusable caller The caller's only uses: is a job-level reusable workflow, which actions.lock does not track; the stale step entries left from the inline scanner made GitHub refuse to start the workflow (startup_failure, jobs=0). Verified: standards check-actions-lock-gate.sh rc=0 and gh actions-lock --no-fix valid=true. gh actions-lock does not rewrite this key itself (D283). Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK --- .github/workflows/actions.lock | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 6cb9a05..5027a00 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -23,10 +23,7 @@ workflows: - 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697' '.github/workflows/push-email-notify.yml': - 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' - '.github/workflows/secret-scanner.yml': - - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' - - 'gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7' - - 'trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d' + '.github/workflows/secret-scanner.yml': [] '.github/workflows/workflow-linter.yml': - 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' dependencies: